Privacy notice pursuant to Article 13 GDPR – Maschinenfabrik Bermatingen GmbH & Co KG Kesselbachstrasse 2, 88697 Bermatingen, Germany
Introduction
The protection of your personal data has the highest priority at Bermatingen; it is considered in all of our business processes.
With the introduction of the EU Data Protection Basic Regulation (GDPR), new and more extensive data protection regulations apply. Given the new legal situation, with the information below we desire to familiarise you with the processing of your personal data by the company and with the rights to which you are entitled under data protection law.
Data is collected for the purpose of operating a website, transmitting data via a contact form and for the writing and reading of cookies. Collection is based on Article 6(1)(a) GDPR and Article 6(1)(f) GDPR. Your visit to this website establishes a material relationship between you and the operator of this website in accordance with Article 6(1)(f) GDPR.
Personal data is defined as any information relating to an identified or identifiable natural person. With this privacy information we inform you of the type, scope and purpose of the collection of personal data by our company and how we handle this data. In addition, you will learn what rights you have with regard to the processing of your personal data.
The following information applies to all natural persons whose personal data are stored and who are associated with the supplier business relationship (e.g. authorised representatives).
Responsible entity (controller) as defined in the Data Protection Act
Maschinenfabrik Bermatingen GmbH & Co. KG
Kesselbachstrasse 2
88697 Bermatingen, Germany
Responsible persons:
MA Business Education (Dipl.-Hdl.) Carmen Gotterbarm
Graduate Engineer (University of Applied Sciences) (Dipl.-Ing.(FH)) Ulrich Gotterbarm
Mr Roderich Gotterbarm
Telephone: +49 7544 95 06 0
Fax: +49 7544 95 06 20
Email: service@mabe-info.de
Internet: www.mabe-info.de
processes your personal data in compliance with the General Data Protection Regulation (GDPR), the Federal Data Protection Act (BDSG) and all other relevant statutory regulations.
The contact details of our data protection officer are as follows:
mwv GmbH
Mr Marc Weiß
Herrenkellergasse 6
89073 Ulm, Germany
mail: zentrale@mwv-ulm.de
www.mwv-ulm.de.
Purpose of the processing
Data is collected for the following purposes
a.) To operate a website
b.) To transmit data in a contact form
c.) To write and read cookies
d.) To evaluate accesses.
e.) To operate a web shop
The following categories of data are processed:
1.) Customer data
- Data processing occurs for the purpose of maintaining the customer relationship.
2.) Suppliers
- Data processing occurs for the purpose of maintaining the supplier relationship.
3.) Personnel/job applicants
- Data processing occurs for the purpose of employee administration.
Data processing occurs for the purpose of recruiting employees.
The data you specify will be stored and processed for the purposes cited above on the basis of Article 6(1)(1)(b) General Data Protection Regulation (GDPR) and Article 6(1)(1)(a) GDPR in conjunction with Article 7 GDPR.
The fields marked as mandatory fields are required to enter into contracts; if the required information is not provided it is possible that the respective transaction cannot be processed. Automated decision-making, including profiling as defined in Article 22(1) and (4) GDPR does not occur.
Measures within the company
All of our employees, who process personal data, are trained in accordance with the GDPR and in accordance with the principles of the GDPR for the processing of personal data they are obligated to comply with the data protection requirements as set forth in Article 5(1) GDPR.
Use and disclosure of personal data
Transfer of personal data to third parties does not occur in principle.
Except: If a legal obligation exists, personal data is transferred to public authorities, such as law enforcement agencies or tax consultants. In addition, personal data will be transferred to third parties only if this is necessary for the purposes cited above, and legally permitted or if you have given your prior consent. Moreover, in the case of prescribed reliability checks, we are obligated to transfer data to official recipients in accordance with Article 6(1)(c) GDPR. In the case of employment of applicants from third countries, data is transferred to the central international and specialist placement service.
Categories of recipients of personal data are: Technical operator of the website, entity responsible for the website (controller) as defined in the GDPR, affiliated group companies, contract processors (processors) as defined in Article 28 GDPR.
Duration of storage
The storage period of your personal data depends on the legal retention periods or the existence of the consent you may have issued.
Right to information
You have extensive rights with regard to the processing of your personal data. It is a matter of particular concern to us to familiarise you with these rights:
Right to information: You have the right to information concerning the data stored at Bermatingen, in particular information concerning the purpose for which processing takes place and how long the data is stored (Article 15 GDPR).
Right to rectification: You have the right to request that we rectify your personal data immediately if it is incorrect (Article 16 GDPR).
Right to erasure: You have the right to request that we erase your personal data. These prerequisites stipulate that you can demand that your data be deleted if, for example, we no longer need the personal data for the purposes for which it was collected, or processed in any other manner, if we process the data unlawfully or if you have legitimately objected to such processing or if there is a statutory obligation to delete it (Article 17 GDPR).
Right to restrict processing: You have the right to request restriction of the processing of your data. In particular, this right exists then exists for the duration of the review, if you have disputed the correctness of the data relating to you and in the event that you desire restricted processing instead of erasure, if there is an existing right to erasure. Moreover, processing will be restricted if the data is no longer required for the purposes pursued by Bermatingen, but you require the data to assert, exercise or defend legal claims, or if the successful exercise of an objection between you and Bermatingen is disputed (Article 18 GDPR). Right to data portability: You have the right to receive from us the personal data relating to you, which you have provided to us, in a structured, common, machine-readable format (Article 20 GDPR), insofar as these data have not already been deleted.
Right to object: You have the right to object to the processing of your personal data at any time for reasons arising from your particular situation (Article 21 GDPR). We will cease processing your personal data, unless we can prove compelling legitimate reasons for the processing that outweigh your interests, rights and freedoms, or if the processing is in the interest of assertion, exercise or defence of legal claims.
If you want to object to the processing of your personal data, please contact us in writing at
Maschinenfabrik Bermatingen GmbH & Co. KG
Kesselbachstrasse 2
88697 Bermatingen, Germany
or by email to service@mabe-info.de
Right to an effective judicial remedy
If you are of the opinion that the processing of your personal data violates the General Data Protection Regulation, please contact the Data Protection Officer cited above or the competent data protection supervisory authority.
Social media
We maintain an online presence on social media networks and platforms in order to communicate with customers, interested parties and users that are active on these social media networks and platforms and to inform these customers, interested parties and users of our products and services.
We expressly state that user data may be processed outside the European Union. Such processing may entail risks for users, e.g. by making it more difficult to enforce users’ rights. With respect to US providers certified under the Privacy Shield, we expressly state that such providers are committed to complying with EU privacy standards.
Moreover as a rule, user data is processed for purposes of market research and advertising. For example, user profiles can be created on the basis of user behaviour and the resulting interests of the users. The user profiles can in turn be used, for example, to place advertisements inside and outside the platforms that are presumed to correspond to the interests of the users. For these purposes, cookies, in which the user’s usage behaviour and interests are saved, are usually stored on the user’s computer. Moreover, data can be stored in the user profiles independently of the devices deployed by the users (particularly if the users are members of the respective platforms and are logged into these platforms).
Processing of users’ personal data occurs on the basis of our legitimate interests in the effective informing of and communicating with users in accordance with Article 6(1)(f) GDPR. If the users are asked by the respective providers for their consent to the data processing (i.e. declare their consent e.g. by ticking a check box or confirming via a button), the legal basis for processing is Article (6)(1)(a), Article 7 GDPR.
For a detailed presentation of the respective processing and the possibilities of objection (Opt-Out), we refer to the linked information of the providers, cited below.
Also in the case of requests for information and for assertion of user rights, we expressly state that requests for information and assertion of user rights can most effectively be enforced with the providers. Only the providers have access to the data of the users and only the providers can directly take appropriate measures and provide information. If you still need help, please do not hesitate to contact us.
Privacy policy for the use of Instagram
The data controller has integrated components of the Instagram service on this website. Instagram is a service that qualifies as an audiovisual platform that enables users to share photos and videos and also to disseminate such data on other social networks.
The operating company of Instagram’s services is Instagram LLC, 1 Hacker Way, Building 14, First Floor, Menlo Park, CA, USA.
Each time one of the individual pages of this website, which is operated by the data controller and on which an Instagram component (Insta button) has been integrated, is accessed, the Internet browser on the information technology system of the data subject (data subject) is automatically prompted by the respective Instagram component to download a representation of the corresponding Instagram component. As part of this technical process, Instagram obtains knowledge of which specific page of our website is being visited by the data subject.
If the data subject is concurrently logged in to Instagram, then Instagram will recognize which specific page the data subject is visiting each time the person visits our website and for the entire duration of that person’s stay on our website. This information is collected by the Instagram component and mapped by Instagram to the Instagram account of the data subject. If the data subject clicks one of the Instagram buttons integrated into our website, the data and information transmitted will be assigned to the personal Instagram user account of the data subject and stored and processed by Instagram.
Instagram receives information from the Instagram component that the data subject has visited our site, whenever the data subject is logged into Instagram at the same time as the data subject is visiting our site, regardless of whether or not they click the Instagram component. If the data subject does not want Instagram to receive such information, the data subject can prevent the transmission by logging out of his/her Instagram account before accessing our website.
For more information and to review Instagram’s current privacy policies, visit https://help.instagram.com/155833707900388 and https://www.instagram.com/about/legal/privacy/.
Vimeo, to which we have no access. You can prevent Google Analytics from tracking you by using the opt-out tools that Google provides for some Internet browsers. You can also prevent Google from collecting the data generated by Google Analytics and related to your use of the website (including your IP address) and prevent Google from processing this data by downloading and installing the browser plug-in available at the following link:
We use Social Plugins (“Plugins”) of the social network facebook.com, which is operated by Facebook Ireland Ltd., 4 Grand Canal Square, Grand Canal Harbour, Dublin 2, Ireland (“Facebook”), on the basis of our legitimate interests (i.e. our interest in the analysis, optimisation and economic operation of our online offering as defined in Article 6(1)(f) GDPR).
This may include, for example, content such as images, videos or texts and buttons, with which users can share content from this online offering within Facebook. The list and appearance of the Facebook Social Plugins can be viewed here https://developers.facebook.com/docs/plugins/.
Facebook is certified under the Privacy Shield Agreement and thus offers a guarantee of compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt0000000GnywAACtatus=Active).
When a user accesses a function of this online service that contains such a plugin, the user’s device establishes a direct connection to the Facebook servers. The content of the plugin is transmitted directly from Facebook to the user’s device and integrated into the online offering by the content of the plugin. User profiles can be created from the processed data. Thus we have no influence on the extent of the data that Facebook collects with the aid of this plugin and we therefore inform the user according to our present state of knowledge.
By integrating the plugins, Facebook receives the information that a user has accessed the respective page of the online offering. If the user is logged in to Facebook, Facebook can assign the visit to his or her Facebook account. When users interact with the plugins, e.g. by clicking the Like button or commenting, the respective information is transferred directly from your device to Facebook and stored at Facebook. If a user is not a member of Facebook, it is still possible for Facebook to know and store the user’s IP address. According to Facebook, only an anonymised IP address is stored in Germany.
The purpose and scope of the data collection and the further processing and use of the data by Facebook, as well as the related rights and settings options to protect the privacy of users, are specified in Facebook’s Privacy Policy https://www.facebook.com/about/privacy/.
If a user is a Facebook member and does not want Facebook to collect information about him or her via this online service and link it to his or her Facebook member data, he or she must log out of Facebook and delete cookies before using our online service. Additional settings and objections to the use of data for advertising purposes are possible within the Facebook profile settings: https://www.facebook.com/settings?tab=ads or via the US website http://www.aboutads.info/choices/ or the EU website http://www.youronlinechoices.com/. The settings are platform-independent, i.e. they will be applied for all devices, such as desktop computers or mobile devices.
Functions and content of the Xing service offered by XING AG, Dammtorstrasse 29-32, 20354 Hamburg, Germany, can be integrated into our online offering. This may include, for example, content such as images, videos or texts and buttons, with which users can share content from this online offer within Xing. If the users are members of the Xing platform, Xing can assign the access of the content and functions cited above to the profiles of the users there. Xing Privacy Policy https://privacy.xing.com/de/datenschutzerklaerung
Functions and content of the Twitter service offered by Twitter Inc., 1355 Market Street, Suite 900, San Francisco, CA 94103, USA, can be integrated into our online offer. This may include, for example, content such as images, videos or texts and buttons with which users can share content from this online service within Twitter.
If the users are members of the Twitter platform, Twitter can assign the access of the content and functions cited above to the profiles of the users there. Twitter is certified under the Privacy Shield Agreement and thus offers a guarantee of compliance with European data protection law (https://www.privacyshield.gov/participant?id=a2zt0000000TORzAAOtatus=Active) Privacy Policy: https://twitter.com/de/privacy, Opt-Out: https://twitter.com/personalization.
YouTube
Privacy policy concerning the use of YouTube
The controller has integrated YouTube components into this website. YouTube is an Internet video portal that allows video publishers to post video clips and other users to view, rate and comment on them free of charge. YouTube allows publication of all types of videos; this is why complete film and television productions, as well as music videos, trailers or videos made by users themselves can be accessed via the Internet portal.
The operating company of YouTube is YouTube, LLC, 901 Cherry Ave, San Bruno, CA 94066, USA. YouTube, LLC is a subsidiary of Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
Each time one of the individual pages of this website, which is operated by the controller and on which a YouTube component (YouTube video) has been integrated, is accessed, the Internet browser on the data subject’s IT system is automatically prompted by the respective YouTube component to download a representation of the corresponding YouTube component from YouTube. Additional information concerning YouTube is provided at https://www.youtube.com/yt/about/de/. As part of this technical process, YouTube and Google obtain information about which specific subpage of our website is being visited by the data subject.
If the data subject is logged into YouTube at the same time, YouTube recognizes which specific subpage of our website the data subject is visiting at access to a subpage containing a YouTube video. This information is collected by YouTube and Google and assigned to the respective YouTube account of the data subject.
YouTube and Google receive information through the YouTube component that the data subject has visited our website, whenever that person is logged into YouTube at the same time as accessing our website, regardless of whether that person clicks on a YouTube video or not. If such transmission of this information to YouTube and Google is not intended by the data subject, the data subject may prevent such transmission by logging out of his/her YouTube account before accessing our website.
The data privacy policies published by YouTube, which are available at https://www.google.de/intl/de/policies/privacy/, provide information about the collection, processing and use of personal data by YouTube and Google.
Google Analytics
Privacy policy for the use of Google Analytics (with anonymization function)
We, the website operator, have integrated the component, Google Analytics (with anonymisation function), on our website. Google Analytics is a web analysis service. Web analysis is the collection and evaluation of data concerning the behaviour of visitors to Internet sites. A web analysis service collects data concerning, for instance, the website from which a data subject has accessed a different website (so-called referrers), what subpages of the website have been accessed or how often and for how long a subpage has been viewed. Web analysis is mainly used for optimization of a website and for cost/benefit analysis of Internet advertising.
The operating company of the Google Analytics component is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland.
On this website we use the extension “_gat._anonymizeIp” for web analysis via Google Analytics. This extension is used by Google to shorten and anonymise the IP address of the Internet connection of the data subject, if access to our Internet pages is from a Member State of the European Union or from another State party to the Agreement on the European Economic Area.
The purpose of the Google Analytics component is to analyse the flow of visitors to our website. Google uses the data and information obtained, among other things, to evaluate the use of our website, to compile online reports for us showing the activities on our website and to provide other services in conjunction with the use of our website.
Google Analytics places a cookie on the information technology system of the data subject. By placing the cookie, Google is able to analyse the use of our website. Each time one of the individual pages of this website, which is operated by the controller and on which a Google Analytics component has been integrated, is accessed, the Internet browser on the data subject’s IT system is automatically prompted by the respective Google Analytics component to transmit data to Google for purposes of online analysis. As part of this technical process, Google obtains knowledge of personal data, such as the IP address of the data subject, which Google uses, for instance, to track the origin of visitors and clicks and subsequently to enable commission billings.
The cookie is used to store personal information, such as access time, the location from which an access originated, and the frequency of visits to our website by the data subject. Each time you visit our website, this personal data, including the IP address of the Internet connection used by the data subject, is transmitted to Google in Ireland. This personal data is stored by Google in Ireland. Under certain circumstances Google shares this personal information, which is collected through the technical process, with third parties.
The data subject can prevent the placing of cookies through our website at any time, as described above, by means of an appropriate setting of the Internet browser used and thus permanently object to the placement of cookies. Such a setting of the Internet browser used would also prevent Google from placing a cookie on the information technology system of the data subject. In addition, a cookie already placed by Google Analytics can be deleted at any time via the Internet browser or other software programs.
Moreover, it is possible for the data subject to object to and prevent the collection of data generated by Google Analytics and relating to the use of this website and the processing of this data by Google. To do this, the data subject must download and install a browser add-on at the link https://tools.google.com/dlpage/gaoptout. This browser add-on tells Google Analytics via JavaScript that no data and information about visits to Internet pages may be transmitted to Google Analytics. Installation of the browser add-on is considered by Google as an objection. If the data subject’s information technology system is later deleted, formatted or reinstalled, the data subject must reinstall the browser add-on in order to deactivate Google Analytics. If the browser add-on is uninstalled or deactivated by the data subject or by another person within his/her sphere of control, the browser add-on can be reinstalled or reactivated.
Further information and Google’s applicable privacy policy is provided at https://www.google.de/intl/de/policies/privacy/ and http://www.google.com/analytics/terms/de.html. Google Analytics is explained in more detail at this link https://www.google.com/intl/de_de/analytics/.
Campaign Manager (formerly DoubleClick by Google)
This website continues to use Google’s online marketing tool, Campaign Manager. The provider is Google Ireland Limited, Gordon House, Barrow Street, Dublin 4, Ireland. Campaign Manager uses cookies to place ads relevant to users, to improve campaign performance reports, or to prevent a user from seeing the same ads more than once. Google uses a cookie ID to record which ads are placed in what browser and can thus prevent them from being displayed more than once. In addition, Campaign Manager may use cookie IDs to collect conversions related to ad requests. This is the case, for example, when a user sees a Campaign Manager ad and later uses the same browser to call up the advertiser’s website and buy something there. According to Google, Campaign Manager cookies do not contain any personally identifiable information.
Due to the marketing tools we use, your browser automatically establishes a direct connection to Google’s server. We have no influence on the extent and subsequent use of the data collected by Google through use of this tool and therefore inform you according to our present state of knowledge: Through integration of Campaign Manager, Google receives the information that you have accessed the respective part of our website or clicked on one of our ads. If you are registered with a Google service, Google can assign the visit to your account. Even if you are not registered with Google or are not logged into Google, it is still possible for the provider to learn your IP address and to store it.
Moreover the Campaign Manager (DoubleClick Floodlight) cookies that are used enable us to understand whether you are performing any actions on our website after you have viewed or clicked on one of our display/video ads on Google or another platform via Campaign Manager (conversion tracking). Campaign Manager uses this cookie to understand the content, with which you have interacted on our websites, so that we can later send you targeted advertising.
You can prevent participation in this tracking process in several ways: a) by setting your browser software accordingly, in particular, the suppression of third-party cookies will prevent you from receiving any third-party advertisements; b) by disabling the cookies for conversion tracking by setting your browser to block cookies from the domain googleadservices.com, https://www.google.com/settings/ads, this setting will be deleted if you delete your cookies; c) by deactivating the interest-based advertisements of the providers that are part of the “About Ads” self-regulation campaign via the link https://www.aboutads.info/choices, this setting will be deleted if you delete your cookies; d) by permanent deactivation in your browsers Firefox, Internet Explorer or Google Chrome at the link http://www.google.com/settings/ads/plugin, e) via appropriate cookies settings. We expressly state that in this case you may not be able to make full use of all the functions of this offering.
In addition, you can prevent Google from collecting the data generated by the cookies concerning your use of the websites and the processing of this data on the part of Google by downloading and using the form provided at https://support.google.com/adsense/answer/142293?hl=de under “Display Settings”, “Campaign Manager Deactivation Extension”.
More information about Campaign Manager, see https://www.google.de/doubleclick, as well as data privacy at Google in general is provided at: https://www.google.de/intl/de/policies/privacy. Alternatively, you can visit the Network Advertising Initiative (NAI) website at http://www.networkadvertising.org. Google has submitted to the EU-US Privacy Shield, https://www.privacyshield.gov/EU-US-Framework.